News linked to both this project and an event.
Zcash founder Zooko Wilcox stated that Zcash recently distributed over $8 million in retroactive funding to contributors, with several million dollars allocated to reward those who volunteered to protect users during this year's AI vulnerability crisis.
Odaily reports: A wallet linked to the $387.5 million Bitget exploit transferred 2,746 ZEC into Zcash's Ironwood privacy pool on Wednesday across three transactions, worth approximately $3.9 million.The funds account for roughly 15% of the ZEC stolen on September 24. The Ironwood privacy pool can conceal the sender, recipient, and transfer amount, but investigators may still be able to trace the path of funds returning to public addresses through transaction timing and amounts. (CoinDesk)
链上侦探 ZachXBT 发文表示,Bitget 被盗事件中疑似朝鲜关联的攻击者已开始将约 2700 枚 ZEC(约 380 万美元)转入 Zcash 的 Ironwood 屏蔽池。Bitget 热钱包此前共被盗约 1.89 万枚 ZEC,价值约 2830 万美元。
Voting results for the Zcash Q3 Token Holder Targeted Retroactive Funding Program indicate that both bounty proposals for Taylor Hornby, discoverer of the Orchard counterfeit coin vulnerability, have been approved. The awards include a $750,000 vulnerability bounty requested by himself, along with an additional $750,000 bonus nominated by community members, totaling $1.5 million. In accordance with regulations, recipients are required to complete subsequent steps including identity verification (KYC) and fund disbursement.
Xie Jiayin, Head of Greater China at Bitget, announced the latest updates on the security incident, stating that the security team has accurately identified the hackers' attack vectors and methodologies, and obtained details on how the attackers bypassed security protocols. Tracing the attack back to its source is now highly imminent. Third-party security firms Mandiant and SlowMist are continuing their incident investigation and will release a detailed report subsequently. On-chain tracking confirms that approximately $387.5 million in assets were transferred to attacker addresses, an upward revision from the previously estimated $351.6 million. This adjustment simply incorporates ZEC and TRX into the total and does not indicate any new assets were stolen. No other unauthorized transfers have been detected. Bitget stated that all stolen funds at the platform level will be fully covered by the User Protection Fund, ensuring user assets remain unaffected. Bitget has also officially launched its Fund Recovery Bounty Program. Individuals or entities that voluntarily freeze or proactively retrieve attacker funds will be eligible for a 5% bounty, with prior assistance remaining eligible. The platform has published the attacker's addresses, a real-time fund tracking dashboard, and an information submission portal, and pledged to announce withdrawal times by 12:00 PM on September 26.
Bitget CEO Gray Chen posted on X platform that following the security incident, on-chain tracking confirmed the attacker's address received a total of $387.5 million in assets, revised upward from the previously disclosed $351.6 million.Gray Chen stated that the revised amount incorporates Zcash and TRON assets that were not fully accounted for previously, and does not represent newly stolen funds. No unauthorized transfers have occurred since the incident, and the situation remains under control. Bitget has launched a Recovery Bounty Program, offering a 5% bounty to each party that voluntarily assists in freezing the attacker's funds or recovering the funds. The exchange has also launched a real-time tracking dashboard, an information submission portal, and an attacker address API, while supporting reports submitted through Bybit's Lazarus Bounty platform. Bitget is currently making full preparations to resume withdrawals, with a specific withdrawal plan to be announced before 4:00 AM (UTC) on September 26.
Odaily News: A 2021 firmware vulnerability in the hardware wallet Coldcard resulted in insufficient randomness in some recovered seeds. Since July 30, attackers have transferred approximately 1,600 to 1,800 BTC from affected wallets, involving thousands of addresses, with an estimated value exceeding $100 million.Coldcard manufacturer Coinkite stated that it must be assumed that someone used AI to review its public firmware. The vulnerability has existed for about five years, and whether AI was involved in the related attacks has not yet been confirmed.Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent and discovered a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022, which in testing could generate unlimited counterfeit ZEC without a trace. Developers completed the fix within days, and no theft of coins has been confirmed.Statistics from blockchain analytics firm Chainalysis show that on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, an increase of 440%. (Bitcoin.com News)
On-chain analyst ZachXBT (@zachxbt) disclosed that the recently launched 10K PFP NFT project zkSNARKs on the Zcash chain is allegedly a rug pull. The project attracted a total of 16,971 bids via a blind auction, ultimately completing the allocation of 8,000 items at a clearing price of 1.5 ZEC (approximately $2,190). Total trading volume reached 25,305 ZEC (approximately $36.94 million), and refunds totaling 13,309 ZEC (approximately $19.43 million) have been progressively returned. ZachXBT noted that the project raised approximately $17 million, while incorporating a 10% team allocation, 5% royalties, and a minting fee of around $2,000, yet offered zero utility. This mirrors the typical "rug pull" strategy commonly seen in Ordinals-style projects.
Odaily reports: Haseeb Qureshi, managing partner at crypto-focused venture capital firm Dragonfly, has proposed that under current rules, the Zcash development fund should cease operations after its expiration in 2028.Qureshi wrote: "I think this should be the last development fund." He stated that the current fund size is already sufficient to support Zcash's remaining development work, and as the fund's value approaches $100 million, it may face "politicization" risks in the future. According to ZecStats data, as of press time, the Zcash development fund holds 63,962 ZEC, worth approximately $95 million.These remarks come amid ongoing industry discussions about the growing size of the development fund. The previous rise in ZEC's price drove a significant increase in the fund's value. Some also argue that Zcash should continue to maintain the development fund. Paradigm founder Matt Huang said on Wednesday that against the backdrop of improving AI network attack capabilities and the rapid development of quantum computing, the fund is particularly important.
Paradigm co-founder Matt Huang posted on the X platform outlining some views on Zcash. He stated that blockchain ecosystems generally face the challenge of long-term funding sources, especially for public goods financing, and that funding developer funds through an inflation mechanism is a viable approach. He believes that amid the backdrop of AI-enhanced cyberattack capabilities and the rapid development of quantum technology, the Zcash developer fund remains highly significant.Matt Huang also stated that as Zcash gains greater acceptance and adoption as a privacy supplement to Bitcoin, governance relying purely on coin-holder voting may introduce unpredictability and affect its ability to build long-term trust as a monetary asset. Therefore, Zcash is better suited to combining coin-holder voting with other governance approaches. Matt Huang also disclosed that Paradigm is an investor in ZEC and ZODL.In the early hours of today, ZEC briefly broke above $1,385, setting a new all-time high.
According to the latest report released by Grayscale Research Director Zach Pandl, as U.S. federal debt surpasses $40 trillion, Bitcoin's 90-day correlation with the Nasdaq 100 Index has dropped from over 60% to approximately 33%, while its correlation with gold has risen from near zero at the start of the year to above 50%, indicating that Bitcoin is shifting from a high-beta risk asset to an inflation-resistant store of value. Grayscale believes that expanding fiscal deficits and rising long-end interest rates will drive investors toward scarce alternative assets, positioning Bitcoin, Ethereum, and Zcash as primary beneficiaries. Among them, Zcash, featuring financial privacy, quantum resistance, and cross-chain interoperability, is considered to have the potential to challenge Bitcoin's network effect, despite its market capitalization currently accounting for less than 1% of Bitcoin's. Additionally, Grayscale notes that the current Bitcoin bear market has persisted for roughly 10 months, approaching the historical average bear market cycle of 11–12 months. Coupled with a macroeconomic environment that is becoming increasingly supportive, it suggests that current prices may represent a favorable entry point for long-term investors.
Odaily News - Digital asset manager Grayscale's Zcash ETF began trading on NYSE Arca on Tuesday under the ticker ZCSH. The product is the world's first exchange-traded product offering spot exposure to Zcash, allowing investors to track ZEC prices through securities accounts without needing to directly purchase or store the token.ZCSH was formerly known as the Grayscale Zcash Trust, established in October 2017 through a private placement. Grayscale filed an application with the U.S. Securities and Exchange Commission in November 2025 to convert the trust into an ETF, with shareholders holding shares that track the fund's ZEC holdings rather than holding ZEC directly.In May of this year, security researcher Taylor Hornby, using Anthropic's Claude Opus 4.8, discovered a vulnerability in Zcash's Orchard shielded pool that had existed for four years, which could potentially allow attackers to mint counterfeit ZEC. Developers deployed an emergency patch on June 1, but due to privacy mechanisms, it was not possible to cryptographically confirm whether the vulnerability had been exploited.Zcash activated the Ironwood upgrade in July, replacing Orchard with a new shielded pool and introducing accounting rules that limit the amount of ZEC exiting the old shielded pool to no more than the amount entering. Grayscale stated it will monitor the adoption of the Ironwood upgrade, network security, exchange support, and regulatory conditions for privacy assets. (Decrypt)
According to official announcements, Zcash has officially activated the Ironwood NU6.3 network upgrade at mainnet block height 3,428,143 and launched the new shielded pool Ironwood. This upgrade aims to address the previously discovered Orchard soundness vulnerability, improve protocol security, and enhance the independent verifiability of ZEC circulating supply integrity.
: According to on-chain detective Specter’s monitoring, B² Network may have suffered a vulnerability exploit on BNB Chain. The attacker transferred 8.591 million B2, worth $3.86 million, and exchanged them for 5,409 WBNB, worth $3.11 million. The funds were then bridged to Ethereum, and are currently being transferred to Zcash via NEAR Intents. The addresses used for the theft are 0xEc443f7D79835B464FBEAC798d3f92B62d6Ff433 and 0xf977427Ec8e583C55D413061FC205BCD57e8Bf6D.
According to on-chain analyst Specter, B² Network on BNB Chain suffered a hack, resulting in a loss of approximately 8.591 million B2 tokens (approximately $3.86 million). The attacker swapped them for 5409 WBNB (approximately $3.11 million) and bridged to Ethereum, and is currently transferring the funds to Zcash via NEAR Intents.
: Tushar Jain, Managing Partner of Multicoin Capital, stated that the crypto market has bottomed out and entered a turning point. Market sentiment has truly hit rock bottom, recent major hacking incidents and other news have not triggered large-scale sell-offs, application adoption rates continue to rise, and there is a decoupling between price and fundamentals. He maintains a long-term bullish outlook on Solana, believing SOL represents the correct architecture for spot trading and tokenized securities. Simultaneously, he is bullish on Hyperliquid's leading position in the derivatives space and currently holds significant positions in both.Regarding ZEC, he stated that Multicoin has accumulated a considerable proportion of its supply and believes it represents the industry's return to "cypherpunk" values, with the potential to enter the top five by market cap. In terms of position management, he adopts a "three-way split" strategy: immediately buying the first third, dollar-cost averaging the second third, and reserving the final third as flexible capital to cope with significant market downturns. During the Zcash code vulnerability incident, after the team observed and confirmed no hacker exploitation, they significantly increased their positions.
Odaily Zcash's native token ZEC rose over 12% on Tuesday after the team responsible for developing its privacy pool said it is nearing completion of a mathematical proof to confirm that there are no undetectable counterfeit minting vulnerabilities in the latest Zcash shielded pool.The verification work, driven by Project Tachyon, is aimed at Zcash's upcoming Ironwood shielded pool. Zcash founder Zooko Wilcox stated that the project is on the verge of producing a mathematical proof, with the goal of proving that the latest Zcash privacy pool has no undetectable minting vulnerabilities.This development follows the disclosure last month of a serious counterfeit vulnerability in the Zcash Orchard shielded pool. At the time, the flaw sparked market concerns about the potential for undiscoverable, hidden inflation risks within Zcash's privacy system, causing ZEC to drop by over 40% within two days.Developers say that with the help of AI-assisted formal verification, proof work that previously might have taken years has now been compressed to a few weeks. The news pushed ZEC back above $500, its highest level since early June. (The Block)
the Zcash development team announced plans to introduce formal verification through the upcoming new privacy pool Ironwood, using mathematical proof methods to eliminate the risk of "Undetectable Counterfeiting."Previously, although the vulnerability in the Orchard shielded pool has been fixed and there is no evidence of exploitation, the community decided to launch a completely new Ironwood shielded pool and perform comprehensive formal verification on its protocol, as it is theoretically impossible to confirm through on-chain history whether covert counterfeiting has occurred.
Odaily Zcash founder Zooko Wilcox posted on X stating that a security audit conducted by Anthropic's Claude Mythos AI model did not find any "more severe vulnerabilities" in the Zcash protocol. The audit was commissioned by Shielded Labs, a Swiss non-profit organization supporting Zcash development. On June 3, Zcash developers temporarily paused Orchard transactions after discovering a vulnerability in the shielded pool, restoring functionality through an emergency upgrade the same day. The issue stemmed from a four-year-old forging vulnerability in the Orchard shielded pool, identified by security researcher Taylor Hornby with the assistance of Anthropic's Claude Opus 4.8 model. The Zcash Foundation stated there is no evidence that the vulnerability was exploited, nor was any unauthorized value creation detected, and user privacy remained unaffected.Anthropic released the first public version of the Claude Mythos model, Fable 5, on Tuesday, and stated on Friday that it has suspended access to the Fable 5 and Mythos 5 AI models due to export control directives issued by the U.S. government citing national security concerns. (Cointelegraph)
According to Cointelegraph, Zcash founder Zooko Wilcox stated that a security audit of the Zcash protocol—commissioned by Shielded Labs and conducted using Anthropic’s Mythos AI model—did not uncover any new critical vulnerabilities. Previously, security researcher Taylor Hornby discovered, using Claude Opus 4.8, a four-year-old forgery vulnerability in the Orchard shielded pool, prompting developers to urgently suspend Orchard transactions on June 3 and complete the fix the same day. The Zcash Foundation confirmed there is no evidence the vulnerability was ever exploited, and user privacy remained unaffected.